Описание
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.
EPSS
Процентиль: 15%
0.00049
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 5.9
github
около 1 года назад
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.
EPSS
Процентиль: 15%
0.00049
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-89